List of Volatility Plugins

The Volatility Framework was designed to be expanded by plugins. Here is a list of the published plugins for the Volatility 1.3 framework. Note that these plugins are not hosted on the wiki, but all on external sites. The latest release of the Volatility Framework is 2.2. These plugins are not compatible with the latest version of the framework and information about compatible plugins can be found on the wiki on the project Googlecode site.

Modified Regripper & Glue Code (By Moyix) - Code to run a modified RegRipper against the registry hives embedded in a memory dump. Note that due to a dependency on Inline::Python, this only works on Linux.

getsids (By Moyix) - Get information about what user (SID) started a process.

ssdt (By Moyix) - List entries in the system call table. Can be used to detect certain rootkits that hook system calls by replacing entries in this table.

threadqueues (By Moyix) - Enumerates window messages pending for each thread on the system. Window messages are the mechanism used to send things like button presses, mouse clicks, and other events to GUI programs.

objtypescan (By Andreas Schuster) - Enumerates Windows kernel object types. (Note: If running the SVN version of Volatility, just install the plugin file from this archive)